Hi all,

Has no-one seen this problem?  If so, wow, what have I done wrong here?

Do you need more info?


Paul Hamilton

Subject: Transparent Proxy going astray

Hi all,

I have watched/lurked on this list for sometime now, and see a Transparent
Proxy question every now or then.  None of them have answered my problem.  I
give it a bash every now and then to see if I will trip over the answer.  It
hasn't worked, so I will try this list again.

I run FreeBSD 4.8 on the gateway, Squid Cache: Version 2.4.STABLE4

Squid.conf has the required lines:

http_port 8080
httpd_accel_port 80
httpd_accel_host virtual
httpd_accel_with_proxy on
httpd_accel_uses_host_header on

and the required ipfw2 firewall rules:

00050        271      27520 allow tcp from to any
00060          3        144 fwd,8080 tcp from any to any dst-port

Interestingly enough when watching the ip traffic on the gateway, I see this
on my inside NIC:

08:27:18.735861 >  1093+ A?
www.google.com.au. (35)
08:27:18.922217 >  1093 2/4/4
08:27:18.923667 > S
813553086:813553086(0) win 16384 <mss 1460,nop,nop,sackOK> (DF)
08:27:18.923722 > R 0:0(0) ack 813553087
win 0
08:27:19.397657 > S
813553086:813553086(0) win 16384 <mss 1460,nop,nop,sackOK> (DF)
08:27:19.397697 > R 0:0(0) ack 1 win 0
08:27:19.906095 > S
813553086:813553086(0) win 16384 <mss 1460,nop,nop,sackOK> (DF)
08:27:19.906153 > R 0:0(0) ack 1 win 0

and this on my outside NIC:

08:27:18.736970 >  1093+ A?
www.google.com.au. (35)
08:27:18.922026 >  1093 2/4/4 CNAME
www.google.com., (215)

The cache_access.log doesn't show any traffic, yet (something) is pretending
to be the google website, as there is a reply from  I have
tried to run tcpdump -ni lo0 but there isn't any traffic.

Should I be able to see traffic on lo0?

Any thoughts on what I am missing?


Paul Hamilton

